SolarWinds Hack — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 24, 2025
Last Seen
November 24, 2025

SolarWinds Hack is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 24, 2025; most recent activity November 24, 2025.

Overview

The SolarWinds Hack refers to a major supply-chain intrusion attributed to a nation-state actor (commonly linked to APT29/Cozy Bear) that compromised the SolarWinds Orion software update mechanism to deliver a backdoor across thousands of organizations, including government and critical infrastructure. It highlighted how trusted software channels can be weaponized, underscoring persistent challenges in supply-chain security and threat-hunting at scale.

Related Threat Clusters

  • Iberia Airlines Data Breach Exposes Customer Information

    Iberia Airlines has informed its customers about a data breach that occurred after a threat actor claimed to have stolen 77GB of data from the airline's systems. The breach affects customer personal details, although…

    14 articles · Updated November 24, 2025
  • Iberia Data Breach Exposes Customer Information via Supplier Incident

    Iberia Airlines disclosed a data breach on November 23, 2025, resulting from unauthorized access to a third-party supplier's systems. The breach exposed sensitive customer information, including names and email…

    14 articles · Updated November 25, 2025

Recent Intelligence Reports

  • Iberia Data Breach Exposes Customer Details via Supplier Vulnerability — Webpronews · November 24, 2025

CVSS v3.1 Breakdown